Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

really awesome that cutting edge crypto is being used by our elected officials & their aides to avoid public records laws!


Worse, they are using it while trying to place back doors in it.


I'm sure they can manage to insert a back door in the legislation, giving themselves a way out.


All legislation is already backdoored by money and the right connections.


Pulling up the ladder after they've climbed it.


Thinking about the last year's worth of stories, there's really no way for them to win here, is there?


Sure... they should just use their (clearnet) government email addresses, secured with mandatory 2FA. If those get hacked it would be potentially embarrassing, but it would be less likely if they all had reasonable security measures.

For any classified material officials can use their SIPRNET/JWICS emails, for which suspicious access is much more closely monitored, of course.


It's worth remembering that the fundamental premise of that position is that the government might be able to field a better security team to protect the most sensitive email in the world than could Google.

Not many security people in the world would sign on to that position.


Eh. At some point, the threat isn't how good your crypto is but rather how much you're willing to sacrifice to keep it that way.

Signal's authors may be more technically competent than a government security officer, but Signal can be coerced into releasing an update that surreptitiously changes the behavior of the application whereas well-protected NSA officers are (theoretically) more immune.


Yeah, now work through how they do that without alerting their targets.


That's not really an issue. The government is perfectly free to use Google Apps for clearnet email.

Do you mean to suggest that Gmail is more secure than government classified networks?


Yes, that is exactly what I mean to suggest.


What gives you that impression?


Competition. Also simple things like spf and tls when many state and federal sites fail at it.


gmail isn't the only thing that govt services "compete" with. Clinton's self-"secured" email server, for example. In that case, we all would have been better off is she had used govt services, for security and for the "sunshine" effect.


No, that's also almost certainly false, because at the time she was doing that, unbeknownst to her, the State Department email servers were completely owned up by Russian hackers.

Clearly, I'd rather Clinton use GApps than run her own email server. But for security, her worst option was the official servers.


Well put. But I don't remember "State servers owned by hackers" as part of the narrative. Is that "inside baseball," or was that reported? I'd think it would be part of the conversation on the Senate's possible investigations in that area now.


It was heavily reported, and it's not unusual: IT security in the USG is a shit-show.


If Hillary Clinton had used Signal instead of her private email server, would it have been ok? (No.)


Would we ever know?


:D:




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: